vendor:
GOM Player
by:
Debasish Mandal & Peter Van Eeckhoutte (corelanc0d3r)
9.3
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: GOM Player
Affected Version From: 2.1.33.5071
Affected Version To: 2.1.33.5071
Patch Exists: YES
Related CWE: N/A
CPE: a:gomlab:gom_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2011
GOM Player Crafted ASX File Unicode Stack Buffer Overflow and Arbitrary Code Execution
This exploit is a crafted ASX file Unicode Stack Buffer Overflow and Arbitrary Code Execution vulnerability in GOM Player version 2.1.33.5071. It allows an attacker to execute arbitrary code on the vulnerable system by sending a specially crafted ASX file. The vulnerability is caused due to a boundary error when handling the title tag of the ASX file. This can be exploited to cause a stack-based buffer overflow by sending a specially crafted ASX file with an overly long title tag.
Mitigation:
Upgrade to the latest version of GOM Player